본문

서브메뉴

Machine Learning Methodologies for Low-Level Hardware-Based Malware Detection
Machine Learning Methodologies for Low-Level Hardware-Based Malware Detection
Machine Learning Methodologies for Low-Level Hardware-Based Malware Detection

상세정보

자료유형  
 학위논문 서양
최종처리일시  
20260202105543
ISBN  
9798263399924
DDC  
621.384
저자명  
Chawla, Nikhil.
서명/저자  
Machine Learning Methodologies for Low-Level Hardware-Based Malware Detection
발행사항  
[Sl] : Georgia Institute of Technology, 2021
발행사항  
Ann Arbor : ProQuest Dissertations & Theses, 2021
형태사항  
138 p
주기사항  
Source: Dissertations Abstracts International, Volume: 87-05, Section: B.
주기사항  
Advisor: Mukhopadhyay, Saibal.
학위논문주기  
Thesis (Ph.D.)--Georgia Institute of Technology, 2021.
초록/해제  
요약Malicious software continues to be a pertinent threat to the security of critical infrastructures harboring sensitive information. The abundance in malware samples and the disclosure of newer vulnerability paths for exploitation necessitates intelligent machine learning techniques for effective and efficient malware detection and analysis. Software-based methods are suitable for in-depth forensic analysis, but their on-device implementations are slower and resource hungry. Alternatively, hardware-based approaches are emerging as an alternative approach against malware threats because of their trustworthiness, difficult evasion, and lower implementation costs. Modern processors have numerous hardware events such as power domains, voltage, frequency, accessible through software interfaces for performance monitoring and debugging. But, information leakage from these events are not explored for defenses against malware threats. This thesis demonstrates approach towards malware detection and analysis by leveraging low-level hardware signatures.The proposed research aims to develop machine learning methodology for detecting malware applications, classifying malware family and detecting shellcode exploits from low-level power signatures and electromagnetic emissions. This includes 1) developing a signature based detector by extracting features from DVFS states and using ML model to distinguish malware application from benign. 2) developing ML model operating on frequency and wavelet features to classify malware behaviors using EM emissions. 3) developing an Restricted Boltzmann Machine (RBM) model to detect anomalies in energy telemetry register values of malware infected application resulting from shellcode exploits. The evaluation of the proposed ML methodology on malware datasets indicate architectureagnostic, pervasive, platform independent detectors that distinguishes malware against benign using DVFS signatures, classifies detected malware to characteristic family using EM signatures, and detect shellcode exploits on browser applications by identifying anomalies in energy telemetry register values using energy-based RBM model.
일반주제명  
Telemetry
일반주제명  
Exploitation
일반주제명  
Malware
일반주제명  
Software upgrading
일반주제명  
Computer viruses
일반주제명  
Energy
일반주제명  
Governors
일반주제명  
Computer science
기타저자  
Georgia Institute of Technology.
기본자료저록  
Dissertations Abstracts International. 87-05B.
전자적 위치 및 접속  
로그인 후 원문을 볼 수 있습니다.

MARC

 008260126s2021        us                              c    eng  d
■001000017360534
■00520260202105543
■006m          o    d                
■007cr#unu||||||||
■020    ▼a9798263399924
■035    ▼a(MiAaPQ)AAI32315393
■035    ▼a(MiAaPQ)GeorgiaTech66100
■040    ▼aMiAaPQ▼cMiAaPQ
■0820  ▼a621.384
■1001  ▼aChawla,  Nikhil.
■24510▼aMachine  Learning  Methodologies  for  Low-Level  Hardware-Based  Malware  Detection
■260    ▼a[Sl]▼bGeorgia  Institute  of  Technology▼c2021
■260  1▼aAnn  Arbor▼bProQuest  Dissertations  &  Theses▼c2021
■300    ▼a138  p
■500    ▼aSource:  Dissertations  Abstracts  International,  Volume:  87-05,  Section:  B.
■500    ▼aAdvisor:  Mukhopadhyay,  Saibal.
■5021  ▼aThesis  (Ph.D.)--Georgia  Institute  of  Technology,  2021.
■520    ▼aMalicious  software  continues  to  be  a  pertinent  threat  to  the  security  of  critical  infrastructures  harboring  sensitive  information.  The  abundance  in  malware  samples  and  the  disclosure  of  newer  vulnerability  paths  for  exploitation  necessitates  intelligent  machine  learning  techniques  for  effective  and  efficient  malware  detection  and  analysis.  Software-based  methods  are  suitable  for  in-depth  forensic  analysis,  but  their  on-device  implementations  are  slower  and  resource  hungry.  Alternatively,  hardware-based  approaches  are  emerging  as  an  alternative  approach  against  malware  threats  because  of  their  trustworthiness,  difficult  evasion,  and  lower  implementation  costs.  Modern  processors  have  numerous  hardware  events  such  as  power  domains,  voltage,  frequency,  accessible  through  software  interfaces  for  performance  monitoring  and  debugging.  But,  information  leakage  from  these  events  are  not  explored  for  defenses  against  malware  threats.  This  thesis  demonstrates  approach  towards  malware  detection  and  analysis  by  leveraging  low-level  hardware  signatures.The  proposed  research  aims  to  develop  machine  learning  methodology  for  detecting  malware  applications,  classifying  malware  family  and  detecting  shellcode  exploits  from  low-level  power  signatures  and  electromagnetic  emissions.  This  includes  1)  developing  a  signature  based  detector  by  extracting  features  from  DVFS  states  and  using  ML  model  to  distinguish  malware  application  from  benign.  2)  developing  ML  model  operating  on  frequency  and  wavelet  features  to  classify  malware  behaviors  using  EM  emissions.  3)  developing  an  Restricted  Boltzmann  Machine  (RBM)  model  to  detect  anomalies  in  energy  telemetry  register  values  of  malware  infected  application  resulting  from  shellcode  exploits.  The  evaluation  of  the  proposed  ML  methodology  on  malware  datasets  indicate  architectureagnostic,  pervasive,  platform  independent  detectors  that  distinguishes  malware  against  benign  using  DVFS  signatures,  classifies  detected  malware  to  characteristic  family  using  EM  signatures,  and  detect  shellcode  exploits  on  browser  applications  by  identifying  anomalies  in  energy  telemetry  register  values  using  energy-based  RBM  model.
■590    ▼aSchool  code:  0078.
■650  4▼aTelemetry
■650  4▼aExploitation
■650  4▼aMalware
■650  4▼aSoftware  upgrading
■650  4▼aComputer  viruses
■650  4▼aEnergy
■650  4▼aGovernors
■650  4▼aComputer  science
■690    ▼a0791
■690    ▼a0800
■690    ▼a0984
■71020▼aGeorgia  Institute  of  Technology.
■7730  ▼tDissertations  Abstracts  International▼g87-05B.
■790    ▼a0078
■791    ▼aPh.D.
■792    ▼a2021
■793    ▼aEnglish
■85640▼uhttp://www.riss.kr/pdu/ddodLink.do?id=T17360534▼nKERIS▼z이  자료의  원문은  한국교육학술정보원에서  제공합니다.

미리보기

내보내기

chatGPT토론

Ai 추천 관련 도서


    신착도서 더보기
    최근 3년간 통계입니다.

    소장정보

    • 예약
    • 소재불명신고
    • 나의폴더
    • 우선정리요청
    • 비도서대출신청
    • 야간 도서대출신청
    소장자료
    등록번호 청구기호 소장처 대출가능여부 대출정보
    TF14789 전자도서 대출가능 마이폴더 부재도서신고 비도서대출신청 야간 도서대출신청

    * 대출중인 자료에 한하여 예약이 가능합니다. 예약을 원하시면 예약버튼을 클릭하십시오.

    해당 도서를 다른 이용자가 함께 대출한 도서

    관련 인기도서

    로그인 후 이용 가능합니다.